Service policy debugging???

Unanswered Question
Aug 13th, 2010

The short of my issue:

I have configured a service policy that watches web traffic to a web server, limiting the maximum connections to the server (over TCP 80) to 'n' amount of simultaneous connections (set connection per-client-max n).  I need to see the pervice policy in action, but the only way I know to do it is to watch the drops in "show service policy" output increment or watch the logging buffer (no syslog server available yet).  I would really like to debug this action.  Is it possible, and most importantly, what is the debug command to do it?

I have this problem too.
0 votes
  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
Marcin Latosiewicz Fri, 08/13/2010 - 08:24


show local-host IP.ADD.RE.SS det

is what you need to "debug" connection counts etc.



Antonio Knox Fri, 08/13/2010 - 09:12

Thanks for your reply.  This was useful info.

But what I'm looking for is a way to run a debug that shows when the 'per-client-max' setting has been invoked?

Kureli Sankar Fri, 08/13/2010 - 10:33

sh service-pol flow tcp host x.x.x.x host y.y.y.y eq 80

sh service-pol flow tcp host x.x.x.x host y.y.y.y eq 443


Antonio Knox Tue, 08/24/2010 - 05:41


For anyone attempting to see on-screen when this service policy is invoked, I've found a simple workaround.  In lieu of a direct debug command, what you can do is configure 'logging monitor errors' and then 'terminal monitoring'  whenever the 'set connection per-client-max n' rule is invoked, you will get a log that looks like this:

/* Style Definitions */ table.MsoNormalTable {mso-style-name:"Table Normal"; mso-tstyle-rowband-size:0; mso-tstyle-colband-size:0; mso-style-noshow:yes; mso-style-priority:99; mso-style-qformat:yes; mso-style-parent:""; mso-padding-alt:0in 5.4pt 0in 5.4pt; mso-para-margin:0in; mso-para-margin-bottom:.0001pt; mso-pagination:widow-orphan; font-size:11.0pt; font-family:"Calibri","sans-serif"; mso-ascii-font-family:Calibri; mso-ascii-theme-font:minor-latin; mso-fareast-font-family:"Times New Roman"; mso-fareast-theme-font:minor-fareast; mso-hansi-font-family:Calibri; mso-hansi-theme-font:minor-latin; mso-bidi-font-family:"Times New Roman"; mso-bidi-theme-font:minor-bidi;}

Aug 17 2010 10:16:48: %ASA-3-201013: Per-client connection limit exceeded 20/20 for input packet from to on interface outside

Hope you find this useful.


This Discussion

Related Content